Faced with rising ransomware risks, companies seeking cybersecurity professionals are paying higher salaries and offering more autonomy
Catherine Stupp / Wall Street Journal :
Context & Ripple Effects
Ransomware has spent a decade scaling from a nuisance into an enterprise-level threat: Cisco's 2016 report counted roughly 9,500 victims paying ransoms monthly at a ~$300 average, and by later reporting attacks had quadrupled and shifted toward whole networks rather than individual PCs. By mid-2021 the pressure had moved from IT departments to corporate balance sheets — the attack surge had already upended the cyber insurance market, raising premiums and underwriting requirements exactly when more companies needed coverage.
The Wall Street Journal's new data point is the labor-market response: with ransomware now a board-level risk, companies competing for cybersecurity professionals are bidding up salaries and ceding more autonomy over how security work gets done. Compensation, not just technology budgets, has become the frontline of ransomware defense.
First-order effects
- Cybersecurity professionals gain direct bargaining power — higher pay offers and greater autonomy mean employers are trading control over security processes to win scarce hires amid active ransomware exposure.
Second-order effects
- Demand spills into adjacent services: vendors like Palo Alto Networks and Sophos later reported rising demand for their ransom negotiators as businesses without in-house expertise outsource talks with cybercriminals.
- Insurers' tightened requirements compound the hiring squeeze — firms facing higher premiums and stricter conditions must staff security capability anyway, pushing total cost-of-defense up beyond salaries alone.
Third-order effects
- If weekend and holiday attacks keep landing harder than weekday ones — by 2022, over a third of surveyed professionals said their firm lost more money from off-hours incidents, per the 1,203-professional survey — security staffing shifts toward always-on coverage models, structurally enlarging the permanent security headcount every company carries.
- The pattern points toward a bifurcated market: elite internal security teams at large firms, and outsourced negotiation-plus-incident-response bundles sold by security vendors to everyone else — defense consolidating around the same platform logic attackers already use.
The trend: As ransomware industrializes, corporate defense is following suit — security talent and incident-response services becoming a permanent, escalating line item rather than a periodic purchase.